Live data from Hacker News

Mullvad: Diskless infrastructure using stboot in beta

mullvad.net

111–120 of 135 posts

Re: Mullvad: Diskless infrastructure using stboot in beta

#111
post #73

Earlier quoted context omitted.

You are allowed to start companies in other countries, and thereby avoid local laws, without moving i.e. changing you country of residence. If you believe any different, please say why so. Just "wouldn’t do them any good" is pretty meaningless.

Your theory is an American could start a company that violates US laws so long as they form the entity somewhere else?

GP didn't say anything like that. They were talking about

> avoid[ing] local laws

(i.e. legally) which is a whole different matter.

Re: Mullvad: Diskless infrastructure using stboot in beta

#112

Earlier quoted context omitted.

Your annoyance is understandable, and yet this question and direct response from a founder is a very informative interaction to have recorded in this thread. Much more informative than if GP had simply stated the results of their Wikipedia research. Sometimes a mediocre question is the landing pad for a great answer. No need to begrudge the question.

While I agree the founder's response was informative, it does not justify the completely erroneous statement/accusation that prompted it. That most certainly should be called out -- especially when it was, at the time, the top voted comment.

People make mistakes. Maybe if you were less you combative your comments would get more upvotes.

Re: Mullvad: Diskless infrastructure using stboot in beta

#113

Earlier quoted context omitted.

Sorry, I should have been more precise: For everyone outside Sweden using Mullvad's Swedish servers. My point was just that the fact that "[r]ight now there is no Swedish law that can compel Mullvad to start logging" does not mean that Swedish intelligence agencies cannot collect any data about you (= the Mullvad user using their Swedish servers).

Locating all their servers in IndependiPrivastan probably wouldn't stop intelligence agencies from collecting data. The NSA, for example, does not care even a tiny bit about the privacy of non-US citizens and sets up equipment around the world to gather and analyze internet traffic.

I agree. But the NSA's resources are also vastly bigger than those of the Swedish intelligence agencies.

Re: Mullvad: Diskless infrastructure using stboot in beta

#114
post #85

Earlier quoted context omitted.

Laws that apply to companies follow different rules than laws that apply to individuals, it feels like you’re conflating the two.. Just because employees reside in Sweden doesn’t mean the company resides in Sweden, legally.

Companies consist of their employees, who have to live somewhere.

A company is a legal entity that is, in many ways, separate from the employees it consists of. I'm surprised there's any disagreement on this point.

Re: Mullvad: Diskless infrastructure using stboot in beta

#115
post #61

Earlier quoted context omitted.

You are allowed to start companies in other countries, and thereby avoid local laws, without moving i.e. changing you country of residence. If you believe any different, please say why so. Just "wouldn’t do them any good" is pretty meaningless.

I assumed it was pretty clear why it wouldn’t do them any good: All of their executives and their staff are in Sweden. It doesn’t matter if the company is registered on Mars, the Swedish government can come knock on their doors, because Swedish laws apply to people in Sweden. The most mundane way to demonstrate this is to imagine they don’t register a company at all. If a bunch of Swedish people get together and star…

> It doesn’t matter if the company is registered on Mars, the Swedish government can come knock on their doors, because Swedish laws apply to people in Sweden.

But it does matter. In most EU countries limited-liability companies (like the Swedish Aktiebolag) are legal entities that are completely separate from their owners and employees. Your idea of Swedish authorities "knocking" on people's doors (who own a company registered abroad) and "convincing" them to hand over customer data appears to be more along to lines of https://xkcd.com/538/ but in this case (in the particular case of a country like Sweden that has a well-respected legal system) it doesn't seem to be grounded in reality.

For instance, Swedish law likely compells companies to hand over customer data under certain circumstances. But if you're the "just" the owner of that (limited-liability) company, the company's customers are not your customers, so authorities cannot compell you to give them access to those customers' data (because you are a separate legal entity).

Re: Mullvad: Diskless infrastructure using stboot in beta

#116

Earlier quoted context omitted.

> Because it's a swedish company? I'm not sure what point you're trying to make. If online privacy is as important to them as they say, they could have easily registered their company (or a subsidiary) in a different EU member state. > They'd have to provide government access if there is a lawsuit that demands it. IANAL but I am not entirely sure this is true in the EU. Either way, my question was "Why are the server…

Really? How easy is it to create a company in another EU country. In the US, it is mostly painless to create a company in another state. Fill out some forms online and pay a few hundred. If you don’t have a presence there, you have to pay for a registered agent in the state. That’s about $100/yr. You may also need a mailing address, but you can get a post office box that will accept and scan your mail for another hun…

To my knowledge here in Germany registering a company is pretty much the same whether you're from Germany or from a different EU country. You don't need to live in Germany or anything.

Of course you still need to know your way around local taxes, legal obligations (of the shareholder, of the company) etc. etc. but that's the case anywhere in the world.

Re: Mullvad: Diskless infrastructure using stboot in beta

#117
post #100
post #26

Earlier quoted context omitted.

Correct! Thank you for highlighting that. Here are some additional details for those interested. We intend to make use of TPM for remote attestation of the current boot chain, reproducible builds to provide a strong link from source code to build artifacts, and a transparency log for a historical record of previously used boot chains, artifacts, WireGuard server keys, and related signatures. As dtx1 mentioned elsewhe…

Isn't network monitoring and logging the bigger issue for a VPN service? How can you provide transparency of the network?

> Isn't network monitoring and logging the bigger issue for a VPN service?

Great point. I have a hard time comparing the importance of the integrity of our VPN servers with monitoring and logging of network traffic happening upstream of them without a long discussion of the many nuances. Let’s leave it at; they are both very important issues.

> How can you provide transparency of the network?

That’s very hard. Individual AS’s upstream of the VPN server you’re connected to might change their routing at any moment, and suddenly your traffic makes its way through an unexpected AS or jurisdiction, which may change the monitoring situation completely.

Enabling our users to use multiple hops is one mitigation, another is vetting our data center providers. In collaboration with some of our Internet providers in Europe we have deployed protections on layers below IP. Come to think of it, I don’t think we’ve blogged about that. Thanks!

Re: Mullvad: Diskless infrastructure using stboot in beta

#118
post #54

Earlier quoted context omitted.

> Because it's a swedish company? I'm not sure what point you're trying to make. If online privacy is as important to them as they say, they could have easily registered their company (or a subsidiary) in a different EU member state. > They'd have to provide government access if there is a lawsuit that demands it. IANAL but I am not entirely sure this is true in the EU. Either way, my question was "Why are the server…

I think you’re overthinking this. The people who run the company are based in Sweden. So they registered the company in Sweden, because that’s where they are. Then they hosted the servers in Sweden, because that’s where they are and where the company is registered. Registering the company somewhere else wouldn’t do them any good when they’re living in Sweden, because the legal system isn’t fooled by sleight of hand l…

> Registering the company somewhere else wouldn’t do them any good when they’re living in Sweden, because the legal system isn’t fooled by sleight of hand like that

This isn’t true at all, at least as long as we assume that you’re dealing with the courts and not some secret police.

Re: Mullvad: Diskless infrastructure using stboot in beta

#120

Earlier quoted context omitted.

On linux you can create a network namespace exposing only the wireguard network device, so that applications in that namespace cannot leak traffic. Setting this up, however, is quite fiddly in my experience.

It’s easier and more secure to just create a VM that’s bridged to the VPN interface (regardless of protocol) if you don’t use the VPN for everything but the things you do use it for absolutely must go through it.

I think I like this idea the best - simple, effective, and unbreakable due to config changes or updates.

Plus it gives you a psychological separation between "VPN related activities" and not. Or you just do everything in the VM. Adds a layer security wise as well to protect your physical system.

If you wanted to get really fancy you could have a few different VM's and each one on a different companies VPN

Post reply on HN